cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
370
Views
10
Helpful
5
Replies

Extension Mobility PIN

Chi Fai Leung
Level 1
Level 1

As the EM, that would make the auth. from CM end users' PIN, which cannot sync with the LDAP. Is it possible to make the PIN auth. as LDAP?

1 Accepted Solution

Accepted Solutions

Mohammed Khan
Cisco Employee
Cisco Employee

Hi Chi Fai,

If i understand correctly you want to authenticate EM User's PIN via LDAP which is not possible because Enduser PIN Residences on CUCM Database and its not a standard attribute of LDAP Hence PIN cannot be authenticated by LDAP.

HTH,

Regards,

Mohammed Noor

View solution in original post

5 Replies 5

Mohammed Khan
Cisco Employee
Cisco Employee

Hi Chi Fai,

If i understand correctly you want to authenticate EM User's PIN via LDAP which is not possible because Enduser PIN Residences on CUCM Database and its not a standard attribute of LDAP Hence PIN cannot be authenticated by LDAP.

HTH,

Regards,

Mohammed Noor

So sad ... util now, the auth. still cannot be unified.

Just wondering, why would you prefer it to be authenticated against the LDAP database?

So far I have always loved it against the CCM, just because If something needs to be changed wrt PIN, I dont have to explain all the things to a Windows Admin ;-)

 

 

I can understand wanting it to auth against LDAP. 

It's one less password for the customer to worry about. 

Well, the PIN is supposedly to be entered by the user at the time of logging into the Phone, using EM Profile and it is Numeric, which makes it easier to be entered.

If the PIN also considered as Password for the CCM/user account, then it opens up for security flaw (imho)

And if the PIN also goes against the LDAP database, then everytime a user's phone has locked out, one will have to speak to the LDAP Admin / Windows Admin :-(

 

(Not very pleasant, imho)